User-initiated enrollment enabled for iOS devices in Jamf Pro
Okta Device Trust enabled on the Okta instance
Apps utilizing SAML or WS-FED
In addition, apps must be configured to only allow access with Device Trust. This requires removing display of the app from Okta Mobile.